Summary
CVE-2026-82270 is a server-side request forgery (SSRF) vulnerability in Portkey AI Gateway, an open-source AI gateway/proxy used to route requests to LLM providers. The flaw lies in the /v1/proxy/* route, which lacks the requestValidator middleware that validates destination hosts elsewhere in the gateway. It carries a CVSS score of 8.7 (high severity) and can allow an attacker to force the gateway to send authenticated requests to internal or arbitrary network destinations.
Technical details
- Root cause: The
/v1/proxy/*route does not enforce therequestValidatormiddleware that normally restricts the destination host for outbound requests made by the gateway. - Trigger condition: An attacker sends a request to the proxy route while setting the
x-portkey-custom-hostheader to an internal address (e.g., a cloud metadata endpoint or internal service) or an otherwise attacker-controlled host. - Attack vector: Network — no authentication to the internal target and no user interaction are required beyond reaching the exposed gateway endpoint.
- Impact: The gateway forwards the request — including the
Authorizationheader — to the attacker-specified host, allowing internal services to be reached and provider API keys/credentials to be exfiltrated to a host of the attacker’s choosing.
Affected software
- Portkey AI Gateway (
@portkey-ai/gateway), versions 1.14.0 through 1.15.2 (inclusive)
Severity
- CVSS v3.1 Base Score: 7.5 (High) —
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N - CVSS v4.0 Base Score: 8.7 (High) —
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Mitigation and recommended actions
- Immediate: Upgrade Portkey AI Gateway to a version beyond 1.15.2 that enforces the
requestValidatormiddleware (including allow-listing of trusted hosts) on the/v1/proxy/*route. - If no patch is available yet: Restrict or disable the
/v1/proxy/*route at the network/reverse-proxy layer, block or strip thex-portkey-custom-hostheader from external clients, and block outbound gateway traffic to internal ranges and cloud metadata addresses (e.g., 169.254.169.254, 127.0.0.0/8, 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16). - Rotate any provider API keys/credentials that may have transited the gateway prior to remediation.
How IONIX identifies potentially affected assets
IONIX matches the following signal against data already collected when it crawled the asset; identifying the technology sends no request beyond that crawl.
- Raw HTTP response body:
AI Gateway says hey!

